Skip to content

Commit a7c1760

Browse files
committed
fix: use BoundServceAccountTokenVolume de default
1 parent 36917f5 commit a7c1760

File tree

1 file changed

+0
-22
lines changed

1 file changed

+0
-22
lines changed

manifests/0000_20_kube-apiserver-operator_06_deployment.yaml

Lines changed: 0 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,6 @@ spec:
2929
runAsUser: 65534
3030
seccompProfile:
3131
type: RuntimeDefault
32-
automountServiceAccountToken: false # here to prevent deadlock, remove in 4.9
3332
serviceAccountName: kube-apiserver-operator
3433
containers:
3534
- name: kube-apiserver-operator
@@ -56,9 +55,6 @@ spec:
5655
name: config
5756
- mountPath: /var/run/secrets/serving-cert
5857
name: serving-cert
59-
- mountPath: /var/run/secrets/kubernetes.io/serviceaccount
60-
name: kube-api-access
61-
readOnly: true
6258
- mountPath: /tmp
6359
name: tmp-dir
6460
env:
@@ -83,24 +79,6 @@ spec:
8379
- name: config
8480
configMap:
8581
name: kube-apiserver-operator-config
86-
- name: kube-api-access
87-
projected:
88-
defaultMode: 420
89-
sources:
90-
- serviceAccountToken:
91-
expirationSeconds: 3600
92-
path: token
93-
- configMap:
94-
items:
95-
- key: ca.crt
96-
path: ca.crt
97-
name: kube-root-ca.crt
98-
- downwardAPI:
99-
items:
100-
- fieldRef:
101-
apiVersion: v1
102-
fieldPath: metadata.namespace
103-
path: namespace
10482
- name: tmp-dir
10583
emptyDir: {}
10684
nodeSelector:

0 commit comments

Comments
 (0)